A ransomware affiliate known as Hastalamuerte has publicly disclosed details of "The Gentlemen" operation, a notorious ransomware-as-a-service (RaaS) campaign. The leaked information reveals the group's tactics, including the exploitation of FortiGate vulnerabilities and the use of bring-your-own-vulnerable-driver (BYOVD) evasion techniques to bypass security controls. Additionally, the operation employs Qilin split tactics, a sophisticated method to evade detection. The Gentlemen RaaS operation has been linked to various high-profile attacks, and this leak provides valuable insight into the group's modus operandi1. The exposure of these details may aid security professionals in developing more effective countermeasures against similar threats. This leak matters to practitioners because it offers a rare glimpse into the inner workings of a prominent RaaS operation, allowing them to refine their defenses and stay ahead of emerging threats.
Ransomware Affiliate Exposes Details of 'The Gentlemen' Operation
⚡ High Priority
Why This Matters
Security developments continue reshaping the threat landscape — staying informed is the first line of defense.
References
- Infosecurity Magazine. (2026, March 19). Ransomware Affiliate Exposes Details of 'The Gentlemen' Operation. Infosecurity Magazine. https://www.infosecurity-magazine.com/news/ransomware-affiliate-gentlemen/
Original Source
Infosecurity Magazine
Read original →